Network Connection Initiated To Cloudflared Tunnels Domains

 Original Source: [Sigma source]
Title: Network Connection Initiated To Cloudflared Tunnels Domains
Status: test
Description:Detects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
References:
  -https://defr0ggy.github.io/research/Abusing-Cloudflared-A-Proxy-Service-To-Host-Share-Applications/
  -https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/
  -Internal Research
Author: Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems)
Date: 2024-05-27
modified:None
Tags:
  • -'attack.exfiltration'
  • -'attack.command-and-control'
  • -'attack.t1567'
  • -'attack.t1572'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationHostname|endswith:
      -'.v2.argotunnel.com'
      -'protocol-v2.argotunnel.com'
      -'trycloudflare.com'
      -'update.argotunnel.com'

  condition:selection
Falsepositives:
  -Legitimate use of cloudflare tunnels will also trigger this.
Level: medium